Search CVE reports


Toggle filters

1 – 10 of 42162 results

Status is adjusted based on your filters.


CVE-2026-4426

Medium priority
Needs evaluation

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can...

1 affected package

libarchive

Package 18.04 LTS
libarchive Needs evaluation
Show less packages

CVE-2026-4424

Medium priority
Needs evaluation

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A...

1 affected package

libarchive

Package 18.04 LTS
libarchive Needs evaluation
Show less packages

CVE-2026-4395

Medium priority
Needs evaluation

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-4159

Medium priority
Needs evaluation

1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-3849

Medium priority
Needs evaluation

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-3842

Medium priority
Needs evaluation

[Unknown description]

1 affected package

qemu

Package 18.04 LTS
qemu Needs evaluation
Show less packages

CVE-2026-3580

Medium priority
Needs evaluation

In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-channel resistance of ECC...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-3579

Medium priority
Needs evaluation

wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-3549

Medium priority
Needs evaluation

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-3548

Medium priority
Needs evaluation

Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string, and a stack-based overflow...

1 affected package

wolfssl

Package 18.04 LTS
wolfssl Needs evaluation
Show less packages